Daily digest
Friday 19 June 2026
A heavy day: 202 new CVEs, well above the recent average of about 91. Severity skewed high: 16 critical and 93 high, 54% of the total. 3 arrived with exploitation evidence or public exploit code already attached. CoreWCF was the most-affected vendor with 13.
New this day, ranked by depth score
The 12 that matter most of the 202 published.
CVE-2026-55255Critical· 9.9CISA KEVPoCLangflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
CVE-2026-54782Critical· 10.0CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation
CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation
CVE-2026-54051Critical· 9.9Network-AI: Improper Neutralization of Special Elements used in an OS Command
Network-AI: Improper Neutralization of Special Elements used in an OS Command
CVE-2026-52910High· 7.8PoCIn the Linux kernel, the following vulnerability has been resolved: bpf: Free reuseport cBPF prog after RCU grace period. Eulgyu Kim reported the splat below with a repro
In the Linux kernel, the following vulnerability has been resolved: bpf: Free reuseport cBPF prog after RCU grace period. Eulgyu Kim reported the splat below with a repro. [0] The repro sets up a UDP reuseport group with a cBPF prog a…
CVE-2026-48584Critical· 9.9Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network.
Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network.
CVE-2026-45480Critical· 10.0Azure Active Directory Elevation of Privilege Vulnerability
Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-54414Critical· 9.8FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover
FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover. The upload filename is validated by F…
GHSA-h3m5-97jq-qjrfCritical· 9.6OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
CVE-2026-56120Critical· 9.6OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
CVE-2026-55447Critical· 9.6Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
CVE-2026-54900HighPoCOj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling
Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling
CVE-2026-48582Critical· 9.6Microsoft Exchange Online Elevation of Privilege Vulnerability
Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
Most-affected vendors
By CVEs published in the period.